Blog

Notes from inside the tenancy.

Detection engineering, incident response and Microsoft security — written by the analysts doing the work, not a marketing team.

Detection engineering · Aug 2026

Tuning Sentinel analytics rules without drowning in noise

The three rule categories worth your attention first, and the ones most teams leave running for no reason.

Read the post →

Incident response · Aug 2026

What the first hour of a BEC response actually looks like

A walkthrough of containment decisions, in the order we make them.

Microsoft security · Jul 2026

Defender licensing: what you're already paying for

Most organisations own more capability than they've turned on. Here's how to find it.

Threat intelligence · Jul 2026

Threat intel that changes a decision, or it isn't intel

Why feed volume is the wrong metric, and what to ask a provider instead.

Industry · Jun 2026

Sovereignty questions worth asking your SOC provider

Where your data sits, who can read it, and which answers should end the conversation.

Detection engineering · Jun 2026

Building detections for identity attacks in Entra ID

Token theft and consent phishing don't look like classic intrusions. They need their own logic.

Free insights for CISOs & IT leaders

The 5 Hard Truths About SOC Procurement in FY26

Hard questions every CISO, IT leader, and risk owner should be asking (and how to avoid the costly missteps most teams make).

Ready to connect?

Ready to get on board with Tarian Cyber in as few as four hours?

Schedule a discovery call with Australia's Microsoft-native cyber security specialists. Learn how we can strengthen your security posture while maximising your existing investments.